openevidence-incident-runbook

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a defensive instructional framework for clinical incident response. It does not contain any executable scripts, automated network triggers, or dangerous command sequences.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions include explicit safeguards against data leakage, requiring the agent to redact patient and credential data from all outputs. It specifically forbids asking users for passwords, session tokens, or private recovery codes.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebFetch only to retrieve current documentation from the vendor's official domain (openevidence.com), which is standard for maintaining up-to-date guidance.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines clear boundaries for processing incident symptoms, instructing the agent to prioritize clinical emergency procedures over tool output and to validate findings against official citations without replaying potentially malicious or sensitive content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 PM
Security Audit — agent-trust-hub — openevidence-incident-runbook